Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,853 advisories

Loading
nanoid: Integer Overflow or Wraparound High
CVE-2026-73086 was published for nanoid (npm) Sep 1, 2026
alanzabihi Credited to alanzabihi
pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project High
GHSA-2rx9-3g3h-c2jv was published for pnpm (npm) Sep 1, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials High
GHSA-3f6p-5ww8-9rcr was published for mysql2 (npm) Sep 1, 2026
Socket.IO: Engine.IO WebTransport SID DoS High
CVE-2026-59724 was published for engine.io (npm) Aug 31, 2026
ni8walk3r Credited to ni8walk3r
MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true` High
CVE-2026-55215 was published for mariadb (npm) Aug 28, 2026
9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF High
CVE-2026-55641 was published for 9router (npm) Aug 28, 2026
EchoSkorJjj Credited to EchoSkorJjj
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass High
CVE-2026-55638 was published for 9router (npm) Aug 28, 2026
dinhvaren Credited to dinhvaren
SunEditor Embed Plugin has DOM XSS via External Script Element After Iframe Embed High
CVE-2026-54606 was published for suneditor (npm) Aug 26, 2026
Adyej999 Credited to Adyej999
@logtape/syslog: syslog log injection via unescaped control characters and unvalidated SD-NAME keys High
CVE-2026-54511 was published for @logtape/syslog (npm) Aug 26, 2026
Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url` High
CVE-2026-54356 was published for @budibase/server (npm) Aug 26, 2026
KovachVL Credited to KovachVL
@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key High
CVE-2026-55604 was published for @arikusi/deepseek-mcp-server (npm) Aug 25, 2026
232-323 Credited to 232-323 and arikusi arikusi arikusi
consciousness-explorer / sublinear-time-solver MCP export_state has an arbitrary file write High
CVE-2026-55609 was published for consciousness-explorer (npm) Aug 25, 2026
BruceJqs Credited to BruceJqs
Whistle vulnerable to path traversal High
CVE-2026-55629 was published for whistle (npm) Aug 25, 2026
researchersongwu Credited to researchersongwu
Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript High
CVE-2026-55596 was published for @platejs/media (npm) Aug 25, 2026
DavidCarliez Credited to DavidCarliez
browse-mcp has an arbitrary file write via unconfined download and state paths High
CVE-2026-55557 was published for browse-mcp (npm) Aug 25, 2026
novice-22 Credited to novice-22
gasbugs Credited to gasbugs
pickem vulnerable to terminal escape-sequence injection via unsanitized item text High
GHSA-8qx3-8gm5-9cj2 was published for pickem (npm) Aug 25, 2026
Keystone vulnerable to `graphql.maxTake` bypass with negative `take` High
CVE-2026-63421 was published for @keystone-6/core (npm) Aug 21, 2026
Haxset Credited to Haxset
Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors High
CVE-2026-61824 was published for defuddle (npm) Aug 21, 2026
Mr-DJ Credited to Mr-DJ
Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter High
CVE-2026-63462 was published for unleash-server (npm) Aug 21, 2026
kah-ja Credited to kah-ja
NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution High
GHSA-ghvf-qf6h-g8x5 was published for @nocobase/server (npm) Aug 20, 2026
lukehebe Credited to lukehebe
node-opcua: Unbounded nonce cache enables unauthenticated heap exhaustion DoS High
CVE-2026-54156 was published for node-opcua (npm) Aug 20, 2026
stanleytobias Credited to stanleytobias and kgnio kgnio kgnio
ProTip! Advisories are also available from the GraphQL API